Privacy Policy
Last updated:
This Privacy Policy explains how PixelMakers Studio SRL (“PixelMakers”, “Cenavio”, “we”, “us”) handles personal data in connection with cenaviopms.com, Cenavio accounts, hotel operations, direct-booking services, support, and related communications. PixelMakers Studio SRL has its registered office at 23 Ion Campineanu Street, Sector 1, Bucharest, Romania, VAT number RO43917962.
1. Our roles
PixelMakers is generally the data controller for website visitors, prospects, account holders, billing contacts, and our own security and service administration. When a hotel or accommodation provider uses Cenavio to process guest, reservation, stay, payment-reference, or operational data, that customer is the controller and PixelMakers acts as its processor under the customer’s instructions.
If you are a guest, requests about a reservation or hotel record should normally be sent first to the property that collected your data. We will assist the property as required by data-protection law and our agreement.
2. Data we collect
Depending on how you use Cenavio, we may collect:
- identity and contact data, such as name, work email, telephone number, employer, job title, and account identifiers;
- account and organization data, such as properties, roles, permissions, settings, language, and authentication records;
- billing and transaction data, such as plan, invoices, payment status, provider identifiers, refunds, and disputes; we do not intentionally store complete card details;
- guest and reservation data entered by customers, such as contact details, stay dates, room, party, preferences, requests, identity or registration details where legally required, and communication history;
- technical and usage data, such as IP address, device and browser information, timestamps, pages or features used, diagnostics, and security events;
- support and communication data, including messages, attachments, feedback, and call or meeting notes; and
- content submitted to AI-assisted features and the resulting output, subject to the controls described below.
3. Sources
We receive data directly from you, from the organization that gives you access, from accommodation providers using Cenavio, from guests using a direct-booking experience, from connected services you enable, and automatically from devices and service logs. We may also receive business contact data from public sources or referrals.
4. Why we process data
We process personal data to:
- provide, operate, secure, troubleshoot, and improve Cenavio;
- create accounts, authenticate users, manage permissions, and prevent fraud or abuse;
- process reservations, operational workflows, support requests, billing, and connected services on a customer’s instructions;
- communicate service, security, legal, and product information;
- measure performance and understand use of the website and service; and
- comply with legal obligations and establish, exercise, or defend legal claims.
Our legal bases, where GDPR applies, include performance of a contract, steps requested before a contract, legitimate interests in running and protecting the service, compliance with legal obligations, consent where requested, and the customer controller’s documented instructions for processor activities.
5. Cookies and similar technologies
Cenavio uses strictly necessary technologies for authentication, security, session continuity, language preferences, load balancing, and saved choices. We may use optional analytics or marketing technologies only where configured and, when required, after consent. You can control non-essential cookies through the consent interface or browser settings. Blocking necessary cookies may prevent sign-in or core features.
6. How we share data
We share personal data only as needed with:
- the organization and authorized users responsible for the relevant property;
- service providers supporting hosting, databases, content delivery, email, payments, support, monitoring, and AI-assisted features, including Cloudflare, Neon, Sanity, Stripe, and OpenAI where the relevant feature is used;
- connected services enabled by the customer;
- professional advisers, auditors, insurers, authorities, or courts where reasonably necessary; and
- a successor in a merger, financing, reorganization, or sale, subject to appropriate safeguards.
We do not sell personal data. We require processors to protect data and process it only for agreed purposes. The exact providers involved depend on the features a customer enables.
7. International transfers and EU hosting
Cenavio’s primary application data is hosted in the European Union. Some providers or support operations may process limited data from other countries. Where required, we use an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary safeguards where appropriate.
8. Retention
We retain personal data only as long as needed for the purposes described above, the customer’s instructions, security, dispute resolution, and legal obligations. Account and operational data is normally retained for the subscription and a limited export or recovery period afterward. Billing, tax, audit, fraud-prevention, and legal records may be kept longer where law requires. Backup copies expire through scheduled rotation.
9. Security
We use technical and organizational safeguards designed for the nature and risk of the data, including encryption in transit, access controls, organization scoping, database controls, logging, backups, and incident procedures. No method of storage or transmission is completely secure. Customers are responsible for configuring permissions, securing devices, and limiting data to what is necessary.
10. Your rights
Subject to applicable law, you may have rights to access, correct, erase, restrict, or receive your data; object to certain processing; withdraw consent without affecting earlier processing; and complain to a supervisory authority. In Romania, the supervisory authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP).
To exercise rights concerning a hotel reservation or guest record, contact the relevant accommodation provider first. For data controlled by PixelMakers, contact us using the details below. We may verify your identity and will respond within the period required by law.
11. AI-assisted features
When you choose an AI-assisted feature, relevant prompts and context may be sent to the disclosed AI provider to generate a response. Customers must ensure they have authority and a lawful basis for submitted personal data. AI output must be reviewed by a person before consequential use. We configure providers and retention controls appropriate to the feature and do not permit Customer Data to be used to train general-purpose models unless clearly disclosed and lawfully authorized.
12. Children
Cenavio is a business service and is not directed to children. Hotels may need to process limited information about minors as part of a reservation or legal registration requirement; the hotel remains responsible for the lawful basis, notice, minimization, and any required parental authorization.
13. Changes and contact
We may update this Privacy Policy to reflect changes in the service, providers, or law. We will publish the new version and update the date above. We will provide additional notice where a change materially affects your rights.
For privacy questions or rights requests, email mihai@pixelmakers.com. You may also write to PixelMakers Studio SRL, 23 Ion Campineanu Street, Sector 1, Bucharest, Romania.